ai
OWASP ZAP Troubleshooting แก้ปัญหา — คู่มือแก้ไขปัญหาการสแกน

OWASP ZAP Troubleshooting

OWASP ZAP Troubleshooting Security Scanner Proxy Authentication Spider Active Scan CI/CD False Positive Performance
| ปัญหา | สาเหตุ | วิธีแก้ | ความยาก |
|---|---|---|---|
| Proxy ไม่ทำงาน | Port 8080 ชนกับ App อื่น | เปลี่ยน Port ใน Options → Local Proxies | ง่าย |
| SSL Certificate Error | Browser ไม่ Trust ZAP CA | Export ZAP CA → Import ใน Browser | ง่าย |
| Auth Fail | Login Config ผิด | ตั้ง Context Authentication ใหม่ | กลาง |
| Spider ไม่ครบ | SPA/JS rendering | ใช้ Ajax Spider + Import Sitemap | กลาง |
| Scan ช้า | Thread น้อย Rule มาก | เพิ่ม Thread ลด Rule ที่ไม่จำเป็น | ง่าย |
| False Positive มาก | Default Threshold ต่ำ | ปรับ Scan Policy Threshold | กลาง |
เคล็ดลับ

- CA: Import ZAP CA Certificate ใน Browser ก่อนเริ่มสแกน HTTPS
- Auth: ตั้ง Login/Logout Indicator ให้ถูกต้อง ป้องกัน Scan ขณะ Logout
- Ajax Spider: ใช้ Ajax Spider สำหรับ SPA React Angular Vue
- CI/CD: ใช้ Baseline Scan ทุก PR Full Scan ทุกคืน
- False Positive: สร้าง rules.tsv Ignore False Positive ที่ตรวจแล้ว
OWASP ZAP คืออะไร
Open Source Security Scanner OWASP SQL Injection XSS CSRF Active Passive Scan Spider Fuzzer API CI/CD Docker Free Windows macOS Linux
ปัญหาที่พบบ่อยมีอะไร
Proxy Port ชน SSL CA Certificate Auth Login Fail Spider SPA URL Scan ช้า Thread Rule False Positive Threshold Tune Policy
ตั้งค่า Authentication อย่างไร
Context Form-based Login URL POST Data Username Password Indicator Regex User Session Cookie Token Script API Bearer Replacer Header
ใช้ใน CI/CD อย่างไร
Docker ZAP Baseline Scan Full Scan API Scan GitHub Actions GitLab CI Jenkins Threshold Fail Pipeline Report HTML JSON Automation Framework
สรุป
OWASP ZAP Troubleshooting Proxy SSL Authentication Spider Active Scan CI/CD Docker Baseline Full API Scan False Positive Performance





